Back to home

Privacy Policy for Sessions

Last Updated: 10/08/2026

Effective Date: 10/08/2026

1. Introduction

KMY CREATIVE LTD, a company registered in the United Kingdom, operates the SESSIONS mobile application ("App"), available on iOS and Android.

This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

By using the App, you agree to the practices described herein. If you do not agree, please do not use the App.

2. Information We Collect

A. Personal Data You Provide

  • Identity data, including email, username, and user ID (UID).
  • Profile data, including hobbies, interests, and onboarding answers.
  • User content, including songs, lyrics, audio recordings, images, AI prompts, and chat messages.

B. Automatically Collected Data

  • Device info, including model, OS version, hardware specs, and app version.
  • Battery level, used solely for a retro-style UI display and not stored long-term.
  • Usage and error logs, including crash reports and diagnostics collected when errors occur.
  • Product analytics, including screen views, feature usage, app lifecycle events, API and performance metadata, and subscription funnel events (via PostHog).
  • Session recordings, being screenshot-based replays of in-app UI interactions (via PostHog). Recordings may include on-screen user content such as lyrics, chat UI, and project screens, because text and image masking are not enabled. Password fields that use secure entry remain obscured.
  • Analytics identifiers, being a pseudonymous analytics ID before login. After login, your Firebase User ID (UID) is linked. When identified, we may also send email, username or display name, and subscription status or entitlements as person properties.

Analytics and session recordings apply to free and Pro users and may begin when the App launches, including before login.

C. Advertising and Measurement Data

We advertise SESSIONS on Meta platforms (Facebook and Instagram). To understand whether our advertising works, the App shares a limited set of events with Meta Platforms:

  • App events: that the App was installed, that it was opened, and certain in-app milestones such as completing signup.
  • Basic technical data necessary for the event to be recorded, such as device type and app version.

We do not collect or share your device advertising identifier (IDFA on iOS, Google Advertising ID on Android). We have configured the Meta SDK so that advertising identifier collection is disabled. This means we do not track you across other companies' apps and websites.

On iOS, installation measurement is handled through Apple's SKAdNetwork, a privacy-preserving system operated by Apple that reports results in aggregate and does not identify individual users.

We never share your songs, lyrics, audio recordings, images, AI prompts, chat messages, email address, or username with Meta. Your creative work is never used for advertising in any form.

D. Financial Data

We do not collect or store payment details. Subscription management is handled via the Apple App Store, Google Play Store, and RevenueCat. We only receive transaction metadata, such as purchase history and subscription status.

3. How We Use Your Data

PurposeLawful Basis
Account creation and authenticationPerformance of contract
AI feature responses such as Ghost WriterPerformance of contract
Storing and syncing creative projectsPerformance of contract
Personalising AI and project experiencePerformance of contract
Debugging and improving stabilityLegitimate interests
Product analytics, UX improvement, and session replay diagnosticsLegitimate interests
Subscription verification and managementPerformance of contract
Measuring the effectiveness of our advertisingLegitimate interests

We do not sell your personal data. We do not use product analytics or session recordings for advertising. We do not track you across other companies' apps and websites.

AI Processing: Real-Time Only

Your AI prompts and generated responses are processed via OpenAI to provide real-time creative suggestions.

These inputs and outputs are stored temporarily in our systems, including Firestore and n8n, to maintain chat history and project context.

We do not use any of your data, including chat logs, audio, or text, to train our own AI models now or in the future.

We confirm that OpenAI does not use your input to train their public models when accessed via API.

Advertising Measurement

We rely on legitimate interests to measure our advertising, on the basis that the data involved is limited to app events, contains no creative content, and involves no cross-app tracking or advertising identifier.

If you object to this processing, contact us at dan@keepmeyoung.uk and we will stop it for your account.

Once shared, Meta processes this data as an independent controller under its own Data Policy, available at https://www.facebook.com/privacy/policy. We cannot control Meta's subsequent use of it.

4. Third-Party Data Processors

We share data only with trusted processors essential to our operations.

ProcessorPurposeJurisdictionLegal Basis
Google (Firebase)Authentication, database, and file storageUSAUK-US Data Bridge and UK SCCs
OpenAIAI text generationUSAUK SCCs
RevenueCatSubscription managementUSAUK SCCs
PostHogProduct analytics and session replayUSA (PostHog Cloud US)UK SCCs, and UK-US Data Bridge where applicable
Meta Platforms Ireland LtdAdvertising measurement and attributionIreland / USAUK SCCs and Meta's own transfer mechanisms
n8nWorkflow automation and logging (self-hosted on Railway, Europe)Germany (Railway EU)Internal Data Processing Agreement

All processors are contractually bound by data processing agreements and, where required, UK Standard Contractual Clauses (UK SCCs).

5. International Data Transfers

We may transfer your personal data outside the UK, including to processors in the United States, Ireland, and Europe.

We ensure protection using:

  • The UK-US Data Adequacy Decision.
  • UK Standard Contractual Clauses (UK SCCs).
  • Encryption and strict access controls.

Advertising measurement data shared with Meta Platforms may be processed in Ireland, the United States, and other jurisdictions in which Meta operates, under Meta's own transfer safeguards.

You may request a copy of our SCCs by emailing dan@keepmeyoung.uk.

6. App Permissions

PermissionPurposeCan Be Revoked?
MicrophoneRecord audio clips into projectsYes
Photos / MediaImport images and audio into moodboardsYes
InternetRequired for syncing, AI, and multiplayerYes
Battery LevelRetro-style UI display onlyYes

Revoking permissions may disable related features.

We do not request permission to track you across other apps and websites, because we do not do so.

7. Shared Data (Importing Content)

You may send text or media from other apps into Sessions.

This data is processed locally first, in temporary cache, and is only uploaded to our servers if you explicitly save it to a project.

8. Data Retention and Deletion

General Retention

We retain your personal data only as long as necessary to provide the App, fix bugs, or comply with legal obligations.

Product analytics events and session recordings (PostHog) are retained for up to 1 year.

Advertising measurement data shared with Meta is retained according to Meta's own retention policies, over which we have no control.

Account Deletion

You may delete your account at any time via the app settings. When you proceed:

  • Your Firebase Authentication account is permanently deleted (via user.delete()).
  • Your profile data, including email, username, and hobbies, is erased.
  • All project files, chat logs, and content are permanently removed from Firestore and Firebase Storage.
  • A secure deletion process is triggered across all systems, including n8n automation workflows.
  • Your PostHog analytics person profile, related events, and session recordings linked to your account are deleted or disassociated on request.
  • Sharing of advertising events with Meta ceases. Data previously shared must be erased through Meta directly, as they hold it as an independent controller.

Temporary Retention of Logs and Backups

Due to operational and technical requirements:

  • Some system and error logs containing your user ID (UID) may persist for up to 90 days after deletion.
  • During this time, the UID cannot be linked back to your identity via Firebase Auth or profile, as email and profile are gone.
  • Analytics data previously identified with your email or UID requires separate erasure in PostHog. We delete or disassociate it on account deletion request, and any residual analytics data is purged within the 1-year PostHog retention window.
  • After 90 days, remaining crash and system log data is automatically and securely purged. Residual PostHog analytics, if any, are purged within 1 year.

Important: Once your Firebase Auth and profile data are deleted, retained crash and system logs that only contain a UID can no longer be linked to your identity through our account systems. Analytics profiles that were identified with email or UID are handled separately via PostHog erasure as described above.

Crash and system logs are used only for essential technical diagnostics, not for advertising or sale. Product analytics and session recordings are used to understand feature usage and improve the App, not for advertising or sale. Advertising measurement data is limited to app events and is used only to measure our advertising — never sold, and never combined with your creative content. We do not use any user data to train AI models now or in the future.

9. Your Legal Rights

Under UK data protection law, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data, subject to technical limitations.
  • Object to processing for certain purposes, including product analytics, session recordings, and advertising measurement.
  • Withdraw consent, for example for app permissions.
  • Lodge a complaint with the Information Commissioner's Office.

There is currently no in-app toggle to disable analytics, session recordings, or advertising measurement. To object to any of that processing, contact dan@keepmeyoung.uk.

To exercise your rights, contact dan@keepmeyoung.uk. We respond within 30 days.

10. Children's Privacy

The App is not intended for children under 13 years of age. In the UK and EEA, we do not knowingly collect data from individuals under 16 without verifiable parental consent.

Our advertising is targeted only at adults aged 18 and over.

If we become aware of such collection, we will delete the data promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If changes materially affect your rights, we will notify you via an in-app alert.

The "Last Updated" date will change with each revision.

12. Contact Us

Email: dan@keepmeyoung.uk

Postal Address: Flat 6 The Lawn, Ealing Green, London, England, W5 5ER

Data Protection Officer: dan@keepmeyoung.uk

We are committed to transparency, accountability, and your privacy.